Created on
03-17-2025
08:27 AM
Edited on
12-31-2025
07:55 AM
By
Stephen_G
| Description | This article describes the Port Mirroring specific VLANS using ACLs feature. |
| Scope | FortiSwitch v7.x, FortiSwitch Hardware versions 2xx, 4xx, 1xxx, 2xxx, 3xxx. |
| Solution |
Use Cases:
Example:
config switch mirror edit "mirror1" set status active set dst "port15" next end
Access Control List configuration:
config switch acl ingress edit 1 config action set mirror "mirror1" end config classifier set vlan-id 40 end set ingress-interface-all enable <----- Apply to all interfaces. next end
The traffic from VLAN 40 from all the ports is mirrored to port 15, where the sniffer server is receiving the traffic. It can be verified by checking the line rate in port15, RX, and TX should increase.
diagnose switch physical-port linerate port15
Related documents: FortiSwitch documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.